Terabytes of credentials leaked in massive supply-chain attack



The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering.

As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage.

Update:There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported:

These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.

“The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

Post updated to add image.



Source link

  • Related Posts

    Spotify expands audiobooks to over 180 markets

    Spotify announced on Wednesday that it’s expanding audiobook access to over 180 markets worldwide, including regions across Europe, the Americas, the Caribbean, the Middle East, Africa, and Asia. The rollout…

    Continue reading
    Kindle Click Vs Kobo Remote: How Much Of A Difference Is There?

    Wireless and wildly convenient. Amazon/Kobo We may receive a commission on purchases made from links. Page-turning remotes used to be a niche workaround, something readers cobbled together with…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Michael McArdle: What drives the Northern Ireland manager?

    Michael McArdle: What drives the Northern Ireland manager?

    G.H. Bass Collaborated with Karl Lagerfeld on Penny Loafers

    G.H. Bass Collaborated with Karl Lagerfeld on Penny Loafers

    Video shows deadly school bus crash in Florida, 911 calls released

    Video shows deadly school bus crash in Florida, 911 calls released

    Spotify expands audiobooks to over 180 markets

    Spotify expands audiobooks to over 180 markets

    The Best Amazon Prime Big Deal Days Sales End Tonight

    The Best Amazon Prime Big Deal Days Sales End Tonight

    ClaroNav Kolahi Inc. Announces EU MDR Certification for Navient Surgical Navigation System